CVE-2021-22731
26.05.2021, 20:15
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | mcsesp083f23g0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesp083f23g0t_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm043f23f0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm053f1cu0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm063f2cu0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm053f1cs0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm063f2cs0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm083f23f0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm103f2cu0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm083f23f0h_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm103f2cu0h_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm103f2cs0h_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm123f2lg0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm093f1cu0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm093f1cs0_firmware | 𝑥 < 8.22 |
schneider-electric | mcsesm103f2cs0_firmware | 𝑥 < 8.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration